Registry deploy model: GHCR images + pull-based server deploy - #122
Merged
Merged
Conversation
Add image: refs (ghcr.io/${owner}/volx-<svc>:${tag}) to the four app services
alongside build:, so the server pulls pre-built images instead of building from
source. Switch keeper signer secrets to ${SEPOLIA_RPC_URL}/${PRIVATE_KEY} (from
a compose-dir .env or exported shell env) and cloudflared to ${TUNNEL_TOKEN},
dropping the .secrets/*.env file mounts so no source tree is needed on the host.
Rewrite deploy.sh to pull pre-built images and recreate only the services whose digest changed (docker compose pull && up -d), instead of git-pulling and building on the host. Runs from a standalone dir holding just the compose file, clickhouse-init.sql, deploy.sh, and .env. Optional --tunnel enables cloudflared.
Replace the build-on-server deploy with a registry pipeline: a matrix job builds the four backend images and pushes them to GHCR (tags latest + sha) using GITHUB_TOKEN, then the deploy job ships the compose + deploy.sh over Cloudflare SSH and runs the pull-based deploy. No registry or app secrets pass through the deploy step beyond SERVER_SSH_KEY.
…perms Source the server .env in deploy.sh and run docker login ghcr.io when GHCR_TOKEN is set, so private packages pull (public still pull anonymously). Scope packages:write to the build job only; deploy gets contents:read.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Switches the deploy model from build-on-server to pull pre-built images (no source on the host), per the requirement to deploy via Docker images rather than a git checkout.
Changes
docker-compose.prod.yml— the four app services now carryimage: ghcr.io/${owner}/volx-<svc>:${VOLX_TAG:-latest}alongsidebuild:(build for local, image for the server pull). Keeper secrets move to${SEPOLIA_RPC_URL}/${PRIVATE_KEY}(compose-dir.envor exported shell env) and cloudflared to${TUNNEL_TOKEN}, so no.secrets/*.envfile mounts / source tree are required on the host.scripts/deploy.sh— rewritten:docker compose pull && up -d --remove-orphans(recreates only services whose image digest changed) + dangling-image prune. No git, no on-host build. Runs from a standalone dir (compose + clickhouse-init.sql + deploy.sh + .env).--tunnelenables the cloudflared profile..github/workflows/deploy.yml— now a two-stage pipeline:build(matrix: api/engine/ingestion/keeper) → build + push to GHCR withGITHUB_TOKEN, tagslatest+ commit SHA, GHA layer cache.deploy→ ship compose + deploy.sh over Cloudflare SSH, run the pull-based deploy.Server holds only
~/volx-deploy/:docker-compose.prod.yml,clickhouse-init.sql,deploy.sh, and.env(keeper secrets, placed once by hand). No repo clone.One-time setup
SERVER_SSH_KEY(+ optionalSERVER_KNOWN_HOSTS).docker login ghcr.io.~/volx-deploy/.envon the server withSEPOLIA_RPC_URL+PRIVATE_KEY.Compose validated (
config -q); deploy.shbash -nclean; deploy.yml YAML valid (jobs build, deploy; matrix covers all 4 images).